]> git.evergreen-ils.org Git - working/Evergreen.git/commit
Escape TPAC "myopac" output to protect against XSS attacks
authorDan Scott <dan@coffeecode.net>
Wed, 17 Aug 2011 19:36:15 +0000 (15:36 -0400)
committerDan Scott <dan@coffeecode.net>
Wed, 17 Aug 2011 19:39:29 +0000 (15:39 -0400)
commit72a2d5b8855d5d22ca6865a539a4552404cd32a6
tree435d7910694c5c2152b8dde2f24b682ef68316a4
parentf040584c589d77486c39fbd1c77438c48a282200
Escape TPAC "myopac" output to protect against XSS attacks

We're using the Template::Toolkit html and uri filters to ensure that
the usual suspects are escaped at output time to prevent trivial XSS
attacks.

Signed-off-by: Dan Scott <dscott@laurentian.ca>
17 files changed:
Open-ILS/src/templates/default/opac/myopac/circ_history.tt2
Open-ILS/src/templates/default/opac/myopac/circs.tt2
Open-ILS/src/templates/default/opac/myopac/hold_history.tt2
Open-ILS/src/templates/default/opac/myopac/holds.tt2
Open-ILS/src/templates/default/opac/myopac/holds/edit.tt2
Open-ILS/src/templates/default/opac/myopac/lists.tt2
Open-ILS/src/templates/default/opac/myopac/main.tt2
Open-ILS/src/templates/default/opac/myopac/main_pay.tt2
Open-ILS/src/templates/default/opac/myopac/main_payment_form.tt2
Open-ILS/src/templates/default/opac/myopac/main_payments.tt2
Open-ILS/src/templates/default/opac/myopac/prefs.tt2
Open-ILS/src/templates/default/opac/myopac/prefs_notify.tt2
Open-ILS/src/templates/default/opac/myopac/prefs_settings.tt2
Open-ILS/src/templates/default/opac/myopac/receipt_email.tt2
Open-ILS/src/templates/default/opac/myopac/receipt_print.tt2
Open-ILS/src/templates/default/opac/myopac/update_email.tt2
Open-ILS/src/templates/default/opac/myopac/update_username.tt2